The public sector lender Bank of Baroda (BoB) has faced a cyberattack, resulting in the alleged publication of approximately one terabyte (1TB) of data, including records from both corporate and retail banking clients, on the dark web for free.
Details of the Alleged Leak
The leak affects information related to current and savings accounts, loan accounts, internet banking users, Non-Resident Indians (NRIs), as well as data pertaining to corporate banking services and branch and ATM records.
In a statement released by the Mumbai-based lender, a comprehensive forensic investigation was announced, and the bank is cooperating closely with relevant authorities in accordance with applicable regulatory requirements.
Bank's Stance on Security
The bank stated in its Monday announcement that the incident occurred due to the compromise of an employee's email, leading to unauthorized access to certain data. It was promptly detected, and containment measures were immediately implemented. The bank emphasized that its core banking systems were not compromised and remain secure.
Furthermore, BoB stated that it has implemented robust information security protocols and remains committed to maintaining the highest standards in this area, as well as protecting the trust of its customers and stakeholders.
Allegations and Data on the Dark Web
Although no hacker has officially claimed responsibility for the data leak, the hacking group TripleX reportedly announced the publication of this data online. According to information on the darknet monitoring platform Ransomware.live from July 24, the dataset includes between 100,000 and 300,000 customer application forms containing photographs and identification documents provided when opening accounts.
Examples of Past Incidents
Previously, various banks have encountered similar security breaches. In early February 2024, about 5,000 clients of Yes Bank who used a multi-currency prepaid card issued in partnership with BookMyForex were affected by a series of fraudulent transactions. During this incident, transactions totaling $280,000 were approved, but the bank managed to block 688 attempted unauthorized operations, saving approximately $100,000.
In 2024, ICICI Bank, India's second-largest private lender, acknowledged a data glitch that affected nearly 17,000 newly issued credit cards. These cards were mistakenly linked to incorrect users within the bank's digital channels.
In October 2016, data belonging to 3.2 million customers was stolen between May 25 and July 10 from the Yes Bank ATM network managed by Hitachi Payment Services. Malware infected 90 Yes Bank ATMs and Point of Sale (PoS) terminals, leading to the theft of customer data from banks such as State Bank of India (SBI), ICICI Bank, HDFC Bank, and Yes Bank. Of the affected cards, 2.6 million were registered on the Visa and Mastercard platforms, and 600,000 on the RuPay platform. The most affected banks regarding card issuance were SBI, HDFC Bank, ICICI Bank, Yes Bank, and Axis Bank.



